IBM Support

IT24245: USER CAN'T ACCESS CERT:/// DIRECTORY VIA CLI EVEN WITH ADMIN USER

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • It is not possible for the user to display the
    cert:/// and sharedcert:/// directory via the command line
    interface, even if they have appropriate access.
    This affects all users, including admin.
    This happens wen your RBM configuration includes the option
    "Enforce CLI".
    Example error:
    xi52(config)# dir cert:
    % Access Denied - use 'cancel' to exit any submode.
    xi52(config)# dir sharedcert:
    % Access Denied - use 'cancel' to exit any submode.
    

Local fix

  • Turn off  "Enforce CLI " option.
    

Problem summary

  • Newly Implemented RBM Checks that include static Cert Directory
    checks can overwrite RBM policies and prevent read access to
    cert directories.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IT24245

  • Reported component name

    DATAPOWER

  • Reported component ID

    DP1234567

  • Reported release

    760

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-02-28

  • Closed date

    2018-05-17

  • Last modified date

    2018-05-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • 0
    

Fix information

  • Fixed component name

    DATAPOWER

  • Fixed component ID

    DP1234567

Applicable component levels

  • R770 PSY

       UP

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateways"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"760"}]

Document Information

Modified date:
27 September 2021